What is IMTransferAgent on Mac?

Last updated: 2026-08-05

IMTransferAgent is an Apple-supplied background file-transfer broker managed by launchd. It handles iMessage attachments and name-and-photo records, and it may serve additional Apple IDS transfer topics.

What it is

IMTransferAgent is an Apple-supplied background application in macOS. It runs in user space and is managed by launchd. The verified executable is located inside /System/Library/PrivateFrameworks/IMTransferServices.framework/IMTransferAgent.app, and its bundle identifier is com.apple.imtransferservices.IMTransferAgent.

Its best-confirmed role is brokering file transfers for Apple communication services. Sending and receiving iMessage attachments is a major use: when a conversation contains a photo, video or another file, IMTransferAgent can handle the transfer work behind the Messages interface.

That description is useful, but it is not complete. Local Apple system evidence also connects IMTransferAgent to iMessage nickname and name-and-photo operations. Its entitlements permit a wider set of Apple IDS transfer topics as well. Those permissions show that the process is capable of serving more than attachment transfers, but they do not prove that every allowed topic currently sends traffic through it. Apple has not published a complete definition of this private process, so “Apple file-transfer broker” is more accurate than treating it as an attachment-only helper.

Why it talks to the network

Confirmed network triggers include uploading an outgoing iMessage attachment, retrieving an incoming attachment, and transferring iMessage name-and-photo records. These events can happen while Messages is handling content in the background, so IMTransferAgent traffic does not always correspond to something you clicked at that exact moment.

Attachment content is encrypted and uploaded to or retrieved from Apple’s iCloud content-storage infrastructure. Apple’s IDS and APNs systems provide identity, routing and delivery coordination around those transfers. Name-and-photo records use CloudKit.

The process is locally permitted to work with numerous additional Apple IDS topics. That allowlist establishes capability, not current usage: Apple does not publicly document which additional topics, if any, generate network traffic through IMTransferAgent. It would therefore be too categorical to label every connection as an iMessage attachment upload or download.

How much traffic is normal

IMTransferAgent is usually negligible while idle. During a transfer, it can produce a short burst whose size follows the material being moved. A name-and-photo record or small metadata item may use little traffic, while sending or retrieving a photo, video or file can produce traffic comparable with that content.

There is no trustworthy Apple-published normal range for this process. Exact protocol overhead has not been verified, and the amount attributable to Apple services beyond the confirmed Messages-related uses is also unverified. A specific MB threshold would therefore be misleading.

The most useful comparison is with actual transfer activity over the same period. A file-sized burst can be consistent with an attachment upload or download. Repeated or unexplained traffic deserves measurement, but its size alone cannot identify the IDS topic, prove which Apple feature initiated it, or establish that the process is malicious.

Can you turn it off

The practical verdict is to keep IMTransferAgent enabled. Apple provides no documented per-agent switch and no System Settings path for disabling it.

Blocking the process with a firewall or trying to unload it can prevent outgoing attachments from sending. Incoming attachments or shared name-and-photo records may stop downloading, and other Apple features using the same transfer broker may also be disrupted. launchd may restart the agent, while failed transfers may continue to fail or retry.

If the goal is to stop using iMessage, Messages has a separate account control at Messages > Settings > iMessage > Sign Out. That signs the account out of the app; it is not a switch for the shared IMTransferAgent service. Likewise, turning off Messages in iCloud only disables cross-device Messages synchronization. It does not disable iMessage attachment transfers and does not provide a supported way to turn off IMTransferAgent.

What people get wrong

Seeing what it actually used

When the traffic does not line up with transfers you recognize, the next step is to measure IMTransferAgent over the relevant time window instead of guessing from a single connection. Bytetally can show its per-process upload and download totals, which you can compare with the timing and approximate size of recent attachments or profile records. The totals reveal how much it used, but they do not identify an undocumented IDS topic or prove which Apple client initiated every transfer.

Related processes

Common questions

Is IMTransferAgent malware?

The IMTransferAgent application at Apple’s verified system path is supplied with macOS. An unfamiliar CDN hostname or distant server does not by itself indicate malware, but a binary found outside the verified system path should be investigated separately.

Why is IMTransferAgent using so much data?

It can upload outgoing iMessage attachments or download incoming ones, so a burst may be comparable in size to the photos, videos or files being transferred. Apple publishes no reliable per-process traffic range.

Can I disable IMTransferAgent?

Apple provides no documented switch for this agent. Blocking or unloading it can break attachment and name-and-photo transfers and may affect other Apple features that share the broker.

Does turning off Messages in iCloud stop IMTransferAgent?

No. That setting disables cross-device Messages synchronization, but it does not turn off iMessage attachment transfers or provide a supported switch for IMTransferAgent.

See exactly how much it used

Bytetally tracks every process on your Mac separately — upload and download, live and historical. All on-device.

Download Free on the Mac App Store

macOS 14 Sonoma or later · 100% on-device · No account